Some weeks ago I read about this Starbucks case where hackers hijacked laptops on the WiFi network to use the devices computing power to mine cryptocurrency, and I thought it might be interesting perform the attack in a different way.

The goal of this article, is to explain how can be done the attack of MITM (Man(Person)-In-The-Middle) to inject some javascript in the html pages, to force all the devices connected to a WiFi network to be mining a cryptocurrency for the attacker.

The objective is to have a script that performs autonomous attack on the WiFi network. It’s what we have called CoffeeMiner, as it’s a kind of attack that can be performed in the cafes WiFi networks.

1. The Scenario

The scenario will be some machines connected to the WiFi network, and the CoffeeMiner attacker intercepting the traffic between the users and the router.

1.1 Scenario configuration

The real scenario is a WiFi with laptops and smartphones connected. We have tested in this real world scenario, and it works. But for this article, we will see more deeply how to set up in a virtual environment.

We will use VirtualBox to deploy our virtual scenario https://www.virtualbox.org/ .

First of all we need to download some Linux disk image and install it into a VirtualBox machine, for this example we will use Kali Linux images https://www.kali.org/

Once we have the ISO image downloaded, we prepare 3 VBox machines with the Linux image installed.

To configure the defined scenario we need to prepare the machines each one with a role:

Victim

will be the machine that connects to the Router and browse some pages.

Attacker

will be the machine where it runs the CoffeeMiner. Is the machine that performs the MITM.

Router / Gateway

will act as a normal gateway.

Once the attack is performed, the scenario will be:

To configure each one of the machines, we will do the following configuration:

2. CoffeeMiner, understanding the code

2.1 ARPspoofing

First of all, we need to understand how the MITM attack is performed.

From wikipedia:

“In computer networking, ARP spoofing, ARP cache poisoning, or ARP poison routing, is a technique by which an attacker sends (spoofed) Address Resolution Protocol (ARP) messages onto a local area network. Generally, the aim is to associate the attacker’s MAC address with the IP address of another host, such as the default gateway, causing any traffic meant for that IP address to be sent to the attacker instead.”

The code above is a simple HTTP Server that will serve our crypto miner to the victims, when they require it.

The javascript miner, will be placed in the /miner_script directory. In our case, we have used the CoinHivejavascript miner.

2.5 CoinHive crypto miner

CoinHive is a javascript miner for the Monero cryptocurrency (XMR). It can be added to a website, and will use the user CPU power to calculate hashes with the Cryptonight PoW hash algorithm to mine Monero, based on CryptoNote protocol.

CoinHive miner makes sense when user stays in a websit for mid-long term sessions. So, for example, for a website where the users average session is arround 40 seconds, it doesn’t make much sense.

In our case, as we will inject the crypto miner in each one of the HTML pages that victims request, will have long term sessions to calculate hashes to mine Monero.

3. CoffeeMiner, puting all together

The main objective is to tie all the previous concepts in one autonomous deployment. This will be the CoffeeMiner.

The idea is to have the CoffeeMiner script that performs the ARPspoofing attack and set ups the mitmproxy to inject the CoinHive cryptominer into victims HTML pages.

First of all, we need to configure the ip_forwarding and IPTABLES, in order to convert the attacker’s machine into a proxy:

To perform the ARPspoof for all the victims, we will prepare a ‘victims.txt’ file with all the victim’s IP. To read all the victims IPs, we prepare some Python lines, that will get the IPs (and also the gateway IP from the command line args), and performs the ARPspoof for each one of the victim’s IP.

4. Demo

In order to do the demo, we set up the VirtualBox scenario explained above.

If we want to perform the attack manually, we will need the following terminals:

Then, once the ARPspoofing attack is done and the injector and the HTTP Server are ready, we can go to the victim’s machine and browse to a website. The victim’s traffic will go through the attacker machine, and will activate the injector:

As a result, the html pages that the victim is viewing, will have the html lines of code that the attacker has been injected.

4.1 Demo video

In the following video, we can see the complete attack in the scenario, using the coffeeMiner.py script:

VirtualBox demo:

Conclusion

As we have seen, the attack can be easily performed, and also can be deployed to be an autonomous attack in a WiFi network.

Another think to have in mind, is that for a real world WiFi network, is better to perform the process with a powerful WiFi antenna, to reach better all the physical zone.